Skip to main content
Skip table of contents

User Subtype Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
User Subtype MessagesBase RuleUser InformationInformation
User LogonSub RuleUser LogonAuthentication Success
User LogonSub RuleUser LogonAuthentication Success
User LogoffSub RuleUser LogoffAuthentication Success
User LogoutSub RuleUser LogoffAuthentication Success
Authentication Timed OutSub RuleAuthentication TimeoutOther Audit

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip<sip>IP AddressIP address of the traffic’s origin.
user<login>Text\String
N/A
server<domainorigin>Text\StringN/A
msg<object>Text\StringN/A
logdesc

<subject>

<vendorinfo>

Text\StringN/A
group<group>Text\StringN/A
action<command>Text\StringN/A
status

<status>

<tag1>

Text\StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.